Andrew Alaniz

Andrew Alaniz Email and Phone Number

Founder and Principal Consultant @ CipherNorth LLC
Birmingham, AL, US
Andrew Alaniz's Location
Birmingham, Alabama, United States, United States
Andrew Alaniz's Contact Details
About Andrew Alaniz

I am a seasoned technology and cyber security executive. I have over 17 years of experience in financial services, healthcare, consulting, and technology sectors. I have a proven track record of establishing innovative and effective information security and technology programs as an executive for Fortune 50/500 financial services firms as well as a top global bank. In my current role as the Deputy Chief Information Security Officer for Regions Bank, I have oversight and leadership for cyber security operations including Data Protection(includes AI), Threat Detection, Incident Response, Security Operations, Vulnerability Management. My strengths are recognizing talent in people and placing them in positions to be successful, identifying inefficiencies in process in order to improve the experience for internal stakeholders, and establishing teams in order improve morale, find efficiency, and increase execution. I challenge the status quo in order to innovate. I measure success and set expectations for execution in order to ensure teams are successful in all aspects of their life.Chief Information Security Officer | CISO | Enterprise Technology | Artificial Intelligence | GenAI Cybersecurity | Cloud Security | Cloud Migration | DevSecOps | AWS | Azure | Cloud Architecture | Cybersecurity | Enterprise Architecture | Team Builder | Program Builder | Security Architecture | Technology | Cloud Governance | Risk Management

Andrew Alaniz's Current Company Details
CipherNorth LLC

Ciphernorth Llc

View
Founder and Principal Consultant
Birmingham, AL, US
Website:
ciphernorth.com
Employees:
1
Andrew Alaniz Work Experience Details
  • Ciphernorth Llc
    Founder And Principal Consultant
    Ciphernorth Llc
    Birmingham, Al, Us
  • Regions Bank
    Svp, Deputy Ciso
    Regions Bank May 2023 - Present
    Birmingham, Alabama, Us
    Direct security operations supporting one of the largest banks in the United States. Responsible for all cyber security operations including security operations, incident response, logging & monitoring, data protection (including for AI), cryptography, vulnerability management, customer identity and access management, and red team operations.
  • Freddie Mac
    Senior Director Of Enterprise Cyber, Resiliency, And Technology Risk
    Freddie Mac Jul 2022 - May 2023
    Mclean, Va, Us
    Manage technology and cyber risk management teams supporting a Fortune 50 organization critical to the US housing market with over $21B in revenue.
  • Freddie Mac
    Director Of Enterprise Technology Risk
    Freddie Mac Jul 2021 - Jul 2022
    Mclean, Va, Us
    Brought a technology mindset to risk. Hired to build a technology team to manage technology risk. Hired technology talent to assess and reformulate how risk is reviewed within technology organizations.- Result: 2x reduction in time spent assessing technology by risk teams and 5x reduction in time needed from technology teams to assess.Guide and Consult technology teams in risk. Brought into a regulatory project that lacked clear scope and plan. Challenged regulators to define a clear scope, and guided technology teams to project plan would lead to a high probability of success.- Result: Reduction and agreement on scope, and clear expectations for technology teams to execute.Developed a devops and engineering mindset to risk. Much of risk was run ad hoc or at best as waterfall. Established scrum-ban type approach to work management and partnered with engineering teams to approach risk management obligations through engineering PI planning.- Result: Led to improved partnership and decreased unplanned work within engineering functions.Engaged engineering teams as equal. Coming from an engineering background, challenged engineering teams from day one and brought a higher expectation to risk reporting in engineering environments and especially cloud environments.- Result: Established risk metrics for cloud environments and challenged existing metrics for accuracy and scope to improve the visibility into the technology risk management posture.Continuous Assessment mindset. Created a roadmap that would redefine ‘risk assessment’ to align with things like cloud, infrastructure as code, and auto scaling workloads. - Result: Started partnering with risk leadership to steer overall risk strategy to an engineering and technology mindset when assessing risk posture of technology areas.
  • Bbva In The Usa
    Director Of Technical Architecture, Head Of Cloud Security Engineering And Architecture
    Bbva In The Usa Sep 2020 - Jul 2021
    Birmingham, Al, Us
    Lead multiple US architecture, security, and engineering teams of over 40 engineers for US segment of top 50 global bank with over 100k employees and over $45B in revenue.- Maintain previous responsibilities.- Lead technical security resource and liaison- Responsible for developing and leading the Security Architecture program for the US.- Develop and lead the Cloud Governance team and the design and implementation of security and governance in the BBVA US' multi-million dollar public cloud presence.- Leading the Cloud Security Operations team to develop controls and respond to threats.- Oversight and workstream lead for both PCI and all technology implementation related to the integration of BBVA systems with Google Pay (project shutdown midstream)- Lead and manage the enterprise service bus (ESB) teams and other middleware teams for the BBVA US Online Banking Platform as well as other integrated systems going through the ESB.- Oversight and consulting related to the cloud technology aspects of shutting down and decommissioning the ventures/subsidiaries related to the acquisition of the bank.- Collaborated on the architecture for data archival related to decommissioning (related to acquisition) a large cloud technology presence
  • Bbva In The Usa
    Head Of Security Architecture, Technical Information Security Officer (Tiso)
    Bbva In The Usa Dec 2017 - Sep 2020
    Birmingham, Al, Us
    Reporting to the Chief Technology Officer (CTO) and responsible for creating the security architecture and cloud governance programs for BBVA US.- Established the first Security Architecture program that grew to assessing thousands of projects per year.- Created and matured a world class cloud governance program, focused in AWS, and setting BBVA US on a path to be best of class in public cloud adoption.- Identified $500k (~15%) of cost reduction in public cloud spend within the first 6 months- Built an architecture team that grew from 1 to over 10 security architects and analysts and developing paths for non-traditional security and non-security roles to become valuable architects
  • Uab Medicine
    Information Security Architect
    Uab Medicine May 2016 - Dec 2017
    Birmingham, Alabama, Us
    Reporting to the Chief Information Security Officer (CISO) responsible for defining and managing security architecture, incident response, and security life-cycle of projects.- Collaborate with various teams to review, design and architect applications and systems that are deployed. - Responsible for the strategy, roadmap, and implementation of security assessments including vulnerability and penetration testing for the enterprise. This includes defining information requirements to ensure that forensically sound information is available for investigation and analysis, working with teams to ensure the proper tools are in place to gather critical data, and working with vendors to engage in testing. - Responsible for Incident Response for high priority security incidents. This includes managing and coordinating resources across teams and departments as well as communicating risk and status to executives. I led and responded to incidents such as WannaCry and NotPetya.
  • Securit360
    Information Security Consultant
    Securit360 May 2013 - May 2016
    Birmingham, Alabama, Us
    Reporting to the CEO and COO, responsible for leading engagements with clients and managing client relationships.- Lead penetration testing and vulnerability assessment engagements as well as security audits for client networks. I helped build and improve our managed services practice as well as the hosted SIEM application. During my tenure, I worked with one of the largest cities in the US, a number of the top 100 law firms in the US, global architecture firms, energy and utility companies as well as a number of large healthcare companies.The engagements with which I worked helped clients to reduce risks and improve their security programs. I was involved in all of the aspects that help keep organizations secure. This included:- Security Auditing- Risk Assessments- Vulnerability Assessments- Penetration Testing- Security Metrics and Monitoring- Policy and training- Security Program Development- Incident Response and Forensics
  • Sterne Agee
    Information Security Analyst And Sharepoint Architect
    Sterne Agee Apr 2011 - May 2013
    Birmingham, Al, Us
    I held the role of security analyst charged with managing Data Loss Prevention and email security and encryption. I planned and implemented DLP and email encryption for an enterprise of 1200+ users in over 50 branch offices across the country. I was also responsible for improving the defense-in-depth of web security and client security utilizing enterprise security applications through management of IDS/IPS devices as well as web application vulnerability assessments.Also as the SharePoint architect Mr Alaniz spearheaded efforts to plan and migrate the existing SharePoint infrastructure to SharePoint 2010. Mr. Alaniz revamped the HR onboarding process through SharePoint to include automated workflows and dashboards to track talent through the onboarding pipeline.Additional duties included performing some functions of application development management with regard to production web applications and databases. This included deploying code, making changes, and providing some management of on going projects.● Managed hosted IDS/IPS devices and coordination projects associated with web application scanning and vulnerability scanning● Managed and maintain Cisco IronPorts for email security and encryption and data loss prevention● Business Process consulting to lines of business as it pertains to new SharePoint projects● Application management and development for production web applications and databases● Spearheaded efforts to plan and migrate the existing SharePoint infrastructure to SharePoint 2010● Responsible for code deployment to production web application● Managed ongoing security related projects
  • Medseek
    Business Solutions Architect
    Medseek Aug 2010 - Mar 2011
    In this role, I continued many of the responsibilities as a Technical Consultant. I implemented SharePoint 2010 for a large healthcare organization with 5 hospitals in the system and over 10,000 employees. In this engagement, I installed and configured a 5 server SharePoint 2010 farm. This particular phase was focused on a policies and procedures document center. Within this Document Center he created a number of solutions to business problems that included features of SharePoint such as Content Types, custom workflows, and Information Management Policies.I designed and developed solutions based on a client’s business and technical requirements. I delivered preliminary architectural designs for prospective client opportunities involving SharePoint 2010. I was responsible for the overall architecture, implementation and configuration of the companies’ SharePoint Site(s). I also worked with the various teams to improve the overall site designs as well as offer technical sales support to inside and outside sales teams. I acted as an adviser to developers, consultants, and users with regard to configuration and administration of SharePoint 2010.● Responsible for planning, architecting, installing and configuring SharePoint 2010● Added greater role in consulting and architecting solutions internally and externally with SharePoint 2010● Implemented five server SharePoint 2010 farm for a large healthcare organization with five hospitals and over 10,000 employees● Designed and implemented a SharePoint Document Center to manage policies and procedures for the healthcare system● Delivered a solution that was simple, robust, and scalable by utilizing SharePoint Content Types, Workflows, Information Management Policies, and other “out-of-the-box” functionality.
  • Cts, Inc.
    Consultant 2
    Cts, Inc. Apr 2009 - Aug 2010
    Birmingham, Al, Us
    I led the team for CTS Internal IT. In this position, I was responsible for oversight of daily help desk support, project planning and implementation, maintenance of the CTS IT Infrastructure, management of vendor relationships, and working with the management team to maintain CTS' long-term IT goals. I spearheaded efforts to migrate CTS to a virtualized environment internally in order to reduce costs and improve administrative efficiency.I began my career at CTS while finishing my last semester of college at UAB. I was responsible for daily break/fix help desk support for CTS as well as for addressing basic level service requests for clients in the SMB space for the IT Outsourcing group at CTS.I received several promotions through my career with progressively more responsibility. I gained valuable experience leading several projects to implement new services and infrastructure for clients including network configuration, server infrastructure and other Microsoft products. During this time I began to work closely with client stakeholders to define requirements and manage expectations.I eventually took on a leadership role within the IT outsourcing team providing oversight and assistance to other team members. I also began to provide input on project assessment and design as well as implementation of complex projects including clients with multiple physical office locations.
  • Cts, Inc.
    Consultant 1
    Cts, Inc. Jun 2008 - Apr 2009
    Birmingham, Al, Us
  • Cts, Inc.
    Analyst 2
    Cts, Inc. Nov 2007 - Jun 2008
    Birmingham, Al, Us
  • Cts, Inc.
    Analyst 1
    Cts, Inc. May 2007 - Nov 2007
    Birmingham, Al, Us
  • Cts, Inc.
    Intern
    Cts, Inc. Jan 2007 - May 2007
    Birmingham, Al, Us

Andrew Alaniz Skills

Sharepoint Security Windows Server Disaster Recovery Microsoft Sql Server Iis Networking Information Security Management Network Security Information Technology Microsoft Technologies Penetration Testing Project Management Process Improvement Software Project Management Consulting Incident Management Network Administration Web Application Security Vulnerability Scanning Amazon Web Services Hipaa Sdlc Powershell Vmware Vulnerability Management Iso 27001 Security Management Vulnerability Assessment Strategic Planning Nerc Mobile Device Management Information Security Compliance Non Profit Administration Legalsec Security Compliance Wireless Security Security Policy Social Engineering Siem Computer Forensics Firewalls Nonprofits Non Profit Leadership Non Profit Program Development Nonprofit Consulting

Andrew Alaniz Education Details

  • University Of Alabama At Birmingham
    University Of Alabama At Birmingham
    Computer And Information Sciences

Frequently Asked Questions about Andrew Alaniz

What company does Andrew Alaniz work for?

Andrew Alaniz works for Ciphernorth Llc

What is Andrew Alaniz's role at the current company?

Andrew Alaniz's current role is Founder and Principal Consultant.

What is Andrew Alaniz's email address?

Andrew Alaniz's email address is an****@****360.com

What is Andrew Alaniz's direct phone number?

Andrew Alaniz's direct phone number is +120599*****

What schools did Andrew Alaniz attend?

Andrew Alaniz attended University Of Alabama At Birmingham.

What are some of Andrew Alaniz's interests?

Andrew Alaniz has interest in Social Services, Children, Education, Poverty Alleviation, Human Rights.

What skills is Andrew Alaniz known for?

Andrew Alaniz has skills like Sharepoint, Security, Windows Server, Disaster Recovery, Microsoft Sql Server, Iis, Networking, Information Security Management, Network Security, Information Technology, Microsoft Technologies, Penetration Testing.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.